Re: problem with HostbasedAuthentication

Sharad <[email protected]> Fri, 29 Apr 2011 14:04:04 +0530 (IST)
Newsgroups gmane.network.openssh.general
Message-ID <[email protected]>
Use the absolute path of sshd as follows:=0A=0A=0Asudo /etc/ssh/sbin/sshd -=
ddd =0A=0APlease ensure that the path is correct. I don't know if ur sshd e=
xists in /etc/ssh/sbin/sshd.=0A=0ARegards,=0Asharad =0A--- On Fri, 29/4/11,=
 Mahmood Naderan <[email protected]> wrote:=0A=0A> From: Mahmood Naderan=
 <[email protected]>=0A> Subject: Re: problem with HostbasedAuthenticati=
on=0A> To: "Sharad" <[email protected]>=0A> Cc: "secureshell@securityfoc=
us.com" <[email protected]>=0A> Date: Friday, 29 April, 2011, 1=
2:34 PM=0A> Sorry what do you mean?=0A> =A0=0A> mahmood@server:~$ sudo sshd=
 -d=0A> sshd re-exec requires execution with an absolute path=0A> mahmood@s=
erver:~$ sudo sshd -d 3=0A> sshd re-exec requires execution with an absolut=
e path=0A> mahmood@server:~$ sudo sshd -ddd=0A> sshd re-exec requires execu=
tion with an absolute path=0A> =0A> My last post was the debug information =
for=0A> server->client.=0A> =0A> // Naderan *Mahmood;=0A> =0A> =0A> ----- O=
riginal Message -----=0A> From: Sharad <[email protected]>=0A> To: Mahmo=
od Naderan <[email protected]>=0A> Cc: "[email protected]"=
=0A> <[email protected]>=0A> Sent: Friday, April 29, 2011 11:31=
 AM=0A> Subject: Re: problem with HostbasedAuthentication=0A> =0A> Can you =
run debug on server as well using sshd -d. More=0A> -d's mean more debug in=
formation (you can use at the max 3=0A> d's) :D=0A> =0A> Regards,=0A> Shara=
d=0A> --- On Fri, 29/4/11, Mahmood Naderan <[email protected]>=0A> wrote=
:=0A> =0A> > From: Mahmood Naderan <[email protected]>=0A> > Subject: Re=
: problem with HostbasedAuthentication=0A> > To: "Sharad" <sharad2011@yahoo=
.com>=0A> > Cc: "[email protected]"=0A> <secureshell@securityfo=
cus.com>=0A> > Date: Friday, 29 April, 2011, 12:23 PM=0A> > The same thing =
happens with IP=0A> > address=0A> > =A0=0A> > =A0=0A> > mahmood@server:~$ s=
sh -vvv 192.168.1.3=0A> > OpenSSH_5.3p1 Debian-3ubuntu4, OpenSSL 0.9.8k 25 =
Mar=0A> 2009=0A> > debug1: Reading configuration data=0A> /etc/ssh/ssh_conf=
ig=0A> > debug1: Applying options for *=0A> > debug2: ssh_connect: needpriv=
 0=0A> > debug1: Connecting to 192.168.1.3 [192.168.1.3] port=0A> 22.=0A> >=
 debug1: Connection established.=0A> > debug1: identity file /home/mahmood/=
.ssh/identity type=0A> -1=0A> > debug1: identity file /home/mahmood/.ssh/id=
_rsa type=0A> -1=0A> > debug1: identity file /home/mahmood/.ssh/id_dsa type=
=0A> -1=0A> > debug1: Remote protocol version 2.0, remote software=0A> > ve=
rsion OpenSSH_5.3p1 Debian-3ubuntu6=0A> > debug1: match: OpenSSH_5.3p1 Debi=
an-3ubuntu6 pat=0A> OpenSSH*=0A> > debug1: Enabling compatibility mode for =
protocol 2.0=0A> > debug1: Local version string SSH-2.0-OpenSSH_5.3p1=0A> >=
 Debian-3ubuntu4=0A> > debug2: fd 3 setting O_NONBLOCK=0A> > debug1: SSH2_M=
SG_KEXINIT sent=0A> > debug3: Wrote 792 bytes for a total of 831=0A> > debu=
g1: SSH2_MSG_KEXINIT received=0A> > debug2: kex_parse_kexinit:=0A> >=0A> di=
ffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffi=
e-hellman-group14-sha1,diffie-hellman-group1-sha1=0A> > debug2: kex_parse_k=
exinit: ssh-rsa,ssh-dss=0A> > debug2: kex_parse_kexinit:=0A> >=0A> aes128-c=
tr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish=
-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,[email protected]=
=0A> > debug2: kex_parse_kexinit:=0A> >=0A> aes128-ctr,aes192-ctr,aes256-ct=
r,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192=
-cbc,aes256-cbc,arcfour,[email protected]=0A> > debug2: kex_parse=
_kexinit: hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,hmac-ripemd=
[email protected],hmac-sha1-96,hmac-md5-96=0A> > debug2: kex_parse_kexinit: h=
mac-md5,hmac-sha1,[email protected],hmac-ripemd160,hmac-ripemd160@openssh=
.com,hmac-sha1-96,hmac-md5-96=0A> > debug2: kex_parse_kexinit: none,zlib@op=
enssh.com,zlib=0A> > debug2: kex_parse_kexinit: none,[email protected],zlib=
=0A> > debug2: kex_parse_kexinit:=0A> > debug2: kex_parse_kexinit:=0A> > de=
bug2: kex_parse_kexinit: first_kex_follows 0=0A> > debug2: kex_parse_kexini=
t: reserved 0=0A> > debug2: kex_parse_kexinit:=0A> >=0A> diffie-hellman-gro=
up-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group1=
4-sha1,diffie-hellman-group1-sha1=0A> > debug2: kex_parse_kexinit: ssh-rsa,=
ssh-dss=0A> > debug2: kex_parse_kexinit:=0A> >=0A> aes128-ctr,aes192-ctr,ae=
s256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc=
,aes192-cbc,aes256-cbc,arcfour,[email protected]=0A> > debug2: ke=
x_parse_kexinit:=0A> >=0A> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcf=
our128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,a=
rcfour,[email protected]=0A> > debug2: kex_parse_kexinit: hmac-md=
5,hmac-sha1,[email protected],hmac-ripemd160,[email protected],h=
mac-sha1-96,hmac-md5-96=0A> > debug2: kex_parse_kexinit: hmac-md5,hmac-sha1=
,[email protected],hmac-ripemd160,[email protected],hmac-sha1-96=
,hmac-md5-96=0A> > debug2: kex_parse_kexinit: none,[email protected]=0A> > d=
ebug2: kex_parse_kexinit: none,[email protected]=0A> > debug2: kex_parse_kex=
init:=0A> > debug2: kex_parse_kexinit:=0A> > debug2: kex_parse_kexinit: fir=
st_kex_follows 0=0A> > debug2: kex_parse_kexinit: reserved 0=0A> > debug2: =
mac_setup: found hmac-md5=0A> > debug1: kex: server->client aes128-ctr hmac=
-md5=0A> none=0A> > debug2: mac_setup: found hmac-md5=0A> > debug1: kex: cl=
ient->server aes128-ctr hmac-md5=0A> none=0A> > debug1:=0A> SSH2_MSG_KEX_DH=
_GEX_REQUEST(1024<1024<8192)=0A> > sent=0A> > debug1: expecting SSH2_MSG_KE=
X_DH_GEX_GROUP=0A> > debug3: Wrote 24 bytes for a total of 855=0A> > debug2=
: dh_gen_key: priv key bits set: 129/256=0A> > debug2: bits set: 505/1024=
=0A> > debug1: SSH2_MSG_KEX_DH_GEX_INIT sent=0A> > debug1: expecting SSH2_M=
SG_KEX_DH_GEX_REPLY=0A> > debug3: Wrote 144 bytes for a total of 999=0A> > =
debug3: check_host_in_hostfile: filename=0A> > /home/mahmood/.ssh/known_hos=
ts=0A> > debug3: check_host_in_hostfile: match line 1=0A> > debug1: Host '1=
92.168.1.3' is known and matches the=0A> RSA=0A> > host key.=0A> > debug1: =
Found key in /home/mahmood/.ssh/known_hosts:1=0A> > debug2: bits set: 517/1=
024=0A> > debug1: ssh_rsa_verify: signature correct=0A> > debug2: kex_deriv=
e_keys=0A> > debug2: set_newkeys: mode 1=0A> > debug1: SSH2_MSG_NEWKEYS sen=
t=0A> > debug1: expecting SSH2_MSG_NEWKEYS=0A> > debug3: Wrote 16 bytes for=
 a total of 1015=0A> > debug2: set_newkeys: mode 0=0A> > debug1: SSH2_MSG_N=
EWKEYS received=0A> > debug1: SSH2_MSG_SERVICE_REQUEST sent=0A> > debug3: W=
rote 48 bytes for a total of 1063=0A> > debug2: service_accept: ssh-useraut=
h=0A> > debug1: SSH2_MSG_SERVICE_ACCEPT received=0A> > debug2: key: /home/m=
ahmood/.ssh/identity ((nil))=0A> > debug2: key: /home/mahmood/.ssh/id_rsa (=
(nil))=0A> > debug2: key: /home/mahmood/.ssh/id_dsa ((nil))=0A> > debug3: W=
rote 64 bytes for a total of 1127=0A> > debug1: Authentications that can co=
ntinue:=0A> > publickey,password,hostbased=0A> > debug3: start over, passed=
 a different list=0A> > publickey,password,hostbased=0A> > debug3: preferre=
d=0A> >=0A> gssapi-keyex,gssapi-with-mic,gssapi,hostbased,publickey,keyboar=
d-interactive,password=0A> > debug3: authmethod_lookup hostbased=0A> > debu=
g3: remaining preferred:=0A> > publickey,keyboard-interactive,password=0A> =
> debug3: authmethod_is_enabled hostbased=0A> > debug1: Next authentication=
 method: hostbased=0A> > get_socket_address: getnameinfo 8 failed: Name or=
=0A> service=0A> > not known=0A> > debug2: userauth_hostbased: chost server=
.=0A> > debug2: ssh_keysign called=0A> > debug3: ssh_msg_send: type 2=0A> >=
 debug3: ssh_msg_recv entering=0A> > debug1: permanently_drop_suid: 1000=0A=
> > get_socket_address: getnameinfo 8 failed: Name or=0A> service=0A> > not=
 known=0A> > cannot get sockname for fd=0A> > ssh_keysign: no reply=0A> > k=
ey_sign failed=0A> > debug2: we did not send a packet, disable method=0A> >=
 debug3: authmethod_lookup publickey=0A> > debug3: remaining preferred:=0A>=
 keyboard-interactive,password=0A> > debug3: authmethod_is_enabled publicke=
y=0A> > debug1: Next authentication method: publickey=0A> > debug1: Trying =
private key:=0A> /home/mahmood/.ssh/identity=0A> > debug3: no such identity=
: /home/mahmood/.ssh/identity=0A> > debug1: Trying private key: /home/mahmo=
od/.ssh/id_rsa=0A> > debug3: no such identity: /home/mahmood/.ssh/id_rsa=0A=
> > debug1: Trying private key: /home/mahmood/.ssh/id_dsa=0A> > debug3: no =
such identity: /home/mahmood/.ssh/id_dsa=0A> > debug2: we did not send a pa=
cket, disable method=0A> > debug3: authmethod_lookup password=0A> > debug3:=
 remaining preferred: ,password=0A> > debug3: authmethod_is_enabled passwor=
d=0A> > debug1: Next authentication method: password=0A> > [email protected].=
1.3's password:=0A> > =0A> > =0A> > // Naderan *Mahmood;=0A> > =0A> > =0A> =
> ----- Original Message -----=0A> > From: Sharad <[email protected]>=0A=
> > To: Mahmood Naderan <[email protected]>=0A> > Cc: "secureshell@secur=
ityfocus.com"=0A> > <[email protected]>=0A> > Sent: Friday, Apr=
il 29, 2011 11:19 AM=0A> > Subject: Re: problem with HostbasedAuthenticatio=
n=0A> > =0A> > Hi Mahmood,=0A> > =0A> > This line looks out of place. Check=
 that host name is=0A> > getting resolved:=0A> > =0A> > get_socket_address:=
 getnameinfo 8 failed: Name or=0A> service=0A> > not known=0A> > =0A> > I a=
m sure you would have performed the same steps on=0A> both=0A> > hosts. Try=
 establishing connection with IP Address=0A> instead=0A> > of hostname.=0A>=
 > =0A> > Regards,=0A> > Sharad=0A> > --- On Thu, 28/4/11, Mahmood Naderan =
<[email protected]>=0A> > wrote:=0A> > =0A> > > From: Mahmood Naderan <n=
[email protected]>=0A> > > Subject: Re: problem with=0A> HostbasedAuthent=
ication=0A> > > To: "Sharad" <[email protected]>=0A> > > Cc: "secureshel=
[email protected]"=0A> > <[email protected]>=0A> > > Date: Th=
ursday, 28 April, 2011, 11:12 PM=0A> > > Dear Sharad,=0A> > > I am now tryi=
ng to setup a hostbased ssh from=0A> server=0A> > to=0A> > > client (previo=
usly client->server worked fine=0A> based=0A> > on=0A> > > your help). I wa=
nt it to be bidirectional.=0A> > > =A0=0A> > > I did the same thing in reve=
rse (now the client=0A> > becomes=0A> > > server and the server becoms clie=
nt). However=0A> this is=0A> > what I=0A> > > get while trying to ssh from =
server to client:=0A> > > =A0=0A> > > =A0=0A> > > debug3: Wrote 48 bytes fo=
r a total of 1063=0A> > > debug2: service_accept: ssh-userauth=0A> > > debu=
g1: SSH2_MSG_SERVICE_ACCEPT received=0A> > > debug2: key: /home/mahmood/.ss=
h/identity ((nil))=0A> > > debug2: key: /home/mahmood/.ssh/id_rsa ((nil))=
=0A> > > debug2: key: /home/mahmood/.ssh/id_dsa ((nil))=0A> > > debug3: Wro=
te 64 bytes for a total of 1127=0A> > > debug1: Authentications that can co=
ntinue:=0A> > > publickey,password,hostbased=0A> > > debug3: start over, pa=
ssed a different list=0A> > > publickey,password,hostbased=0A> > > debug3: =
preferred=0A> > >=0A> >=0A> gssapi-keyex,gssapi-with-mic,gssapi,hostbased,p=
ublickey,keyboard-interactive,password=0A> > > debug3: authmethod_lookup ho=
stbased=0A> > > debug3: remaining preferred:=0A> > > publickey,keyboard-int=
eractive,password=0A> > > debug3: authmethod_is_enabled hostbased=0A> > > d=
ebug1: Next authentication method: hostbased=0A> > > get_socket_address: ge=
tnameinfo 8 failed: Name=0A> or=0A> > service=0A> > > not known=0A> > > deb=
ug2: userauth_hostbased: chost server.=0A> > > debug2: ssh_keysign called=
=0A> > > debug3: ssh_msg_send: type 2=0A> > > debug3: ssh_msg_recv entering=
=0A> > > debug1: permanently_drop_suid: 1000=0A> > > get_socket_address: ge=
tnameinfo 8 failed: Name=0A> or=0A> > service=0A> > > not known=0A> > > can=
not get sockname for fd=0A> > > ssh_keysign: no reply=0A> > > key_sign fail=
ed=0A> > > debug2: we did not send a packet, disable method=0A> > > debug3:=
 authmethod_lookup publickey=0A> > > debug3: remaining preferred:=0A> > key=
board-interactive,password=0A> > > debug3: authmethod_is_enabled publickey=
=0A> > > debug1: Next authentication method: publickey=0A> > > debug1: Tryi=
ng private key:=0A> > /home/mahmood/.ssh/identity=0A> > > debug3: no such i=
dentity:=0A> /home/mahmood/.ssh/identity=0A> > > debug1: Trying private key=
:=0A> /home/mahmood/.ssh/id_rsa=0A> > > debug3: no such identity:=0A> /home=
/mahmood/.ssh/id_rsa=0A> > > debug1: Trying private key:=0A> /home/mahmood/=
.ssh/id_dsa=0A> > > debug3: no such identity:=0A> /home/mahmood/.ssh/id_dsa=
=0A> > > debug2: we did not send a packet, disable method=0A> > > debug3: a=
uthmethod_lookup password=0A> > > debug3: remaining preferred: ,password=0A=
> > > debug3: authmethod_is_enabled password=0A> > > debug1: Next authentic=
ation method: password=0A> > > [email protected]'s password:=0A> > > =0A>=
 > > =A0=0A> > > What is your suggestion?=0A> > > =0A> > > // Naderan *Mahm=
ood;=0A> > > =0A> > > =0A> > > ----- Original Message -----=0A> > > From: S=
harad <[email protected]>=0A> > > To: Mahmood Naderan <nt_mahmood@yahoo.=
com>=0A> > > Cc: "[email protected]"=0A> > > <secureshell@secur=
ityfocus.com>=0A> > > Sent: Thursday, April 28, 2011 5:20 PM=0A> > > Subjec=
t: Re: problem with=0A> HostbasedAuthentication=0A> > > =0A> > > Mahmood, =
=0A> > > =0A> > > The files are /home/username/.ssh/known_hosts on=0A> both=
=0A> > > server and client.=0A> > > =0A> > > By FQDN, I meant host's fully =
qualified domain=0A> name. =0A> > > =0A> > > Following is the example:=0A> =
> > =0A> > > Assuming both client and server are linux hosts:=0A> > > =0A> =
> > Server IP: 192.168.1.1=0A> > > Client IP: 192.168.1.101=0A> > > =0A> > =
> Server Name: lnx_srvr_1.domain.com=0A> > > Client Name: lnx_clnt_101.doma=
in.com=0A> > > =0A> > > User name on each host is mahmood.=0A> > > =0A> > >=
 Following would be the entries in .shosts on=0A> > lnx_srvr_1=0A> > > =0A>=
 > > =0A> > > lnx_srvr_1:/home/mahmood $ cat .shosts=0A> > > =0A> > > lnx_c=
lnt_101.domain.com mahmood=0A> > > 192.168.1.101 mahmood=0A> > > lnx_clnt_1=
01 mahmood=0A> > > =0A> > > Following should exist in=0A> > /home/mahmood/.=
ssh/known_hosts=0A> > > file on the server side:=0A> > >=0A> 192.168.1.101,=
lnx_clnt_101,lnx_clnt_101.domain.com=A0=0A> > > ssh-rsa AAAAB3Nz...=0A> > >=
 =0A> > > Following should also exist in=0A> > > /home/mahmood/.ssh/known_h=
osts file on the=0A> client=0A> > side:=0A> > > 192.168.1.1,lnx_srvr_1,lnx_=
srvr_1.domain.com=A0=0A> > ssh-rsa=0A> > > AAAAB3Nz...=0A> > > =0A> > > Ens=
ure that .ssh directory on both client and=0A> server=0A> > are=0A> > > rwx=
 for owner only and group/rest of world is=0A> 000.=0A> > > =0A> > > Hope t=
his helps! Good Luck! :)=0A> > > =0A> > > Regards,=0A> > > Sharad=A0 =0A> >=
 > --- On Thu, 28/4/11, Mahmood Naderan <[email protected]>=0A> > > wrot=
e:=0A> > > =0A> > > > From: Mahmood Naderan <[email protected]>=0A> > > =
> Subject: Re: problem with=0A> > HostbasedAuthentication=0A> > > > To: "Sh=
arad" <[email protected]>=0A> > > > Cc: "[email protected]"=
=0A> > > <[email protected]>=0A> > > > Date: Thursday, 28 April=
, 2011, 3:54 PM=0A> > > > Can you explain exactly which file I=0A> > > > sh=
ould edit? What is FQDN? By 'hostname', Do=0A> you=0A> > mean=0A> > > serve=
r=0A> > > > hostname of client hostname. =0A> > > > Should I do that on bot=
h side or server=0A> side?...=0A> > > > =0A> > > > // Naderan *Mahmood;=0A>=
 > > > =0A> > > > =0A> > > > ----- Original Message -----=0A> > > > From: S=
harad <[email protected]>=0A> > > > To: Mahmood Naderan <nt_mahmood@yaho=
o.com>;=0A> > > > Asif Iqbal <[email protected]>=0A> > > > Cc: "secureshell@=
securityfocus.com"=0A> > > > <[email protected]>=0A> > > > Sent=
: Thursday, April 28, 2011 1:16 PM=0A> > > > Subject: Re: problem with=0A> =
> HostbasedAuthentication=0A> > > > =0A> > > > Sometimes the issue lies wit=
h hostname as=0A> well.=0A> > What I=0A> > > mean=0A> > > > with that is th=
e known_hosts may have just=0A> the=0A> > host=0A> > > name=0A> > > > where=
 as when the connection is established,=0A> the=0A> > debug=0A> > > shows=
=0A> > > > the FQDN. I faced this issue so to be sure,=0A> I=0A> > edited=
=0A> > > the=0A> > > > known_hosts file and inserted the hostname,=0A> > ho=
stname's=0A> > > FQDN=0A> > > > and it's IP address (all comma separated).=
=0A> > > > =0A> > > > Also ensure that you both the hosts'=0A> known_hosts=
=0A> > files=0A> > > have=0A> > > > opposite servers names (as prescribed=
=0A> above). =0A> > > > =0A> > > > All the above checks makes it work for m=
e.=0A> > > > =0A> > > > Hope this solves.=0A> > > > =0A> > > > Kind regards=
,=0A> > > > Sharad=0A> > > > --- On Thu, 28/4/11, Asif Iqbal <vadud3@gmail.=
com>=0A> > > > wrote:=0A> > > > =0A> > > > > From: Asif Iqbal <vadud3@gmail=
.com>=0A> > > > > Subject: Re: problem with=0A> > > HostbasedAuthentication=
=0A> > > > > To: "Mahmood Naderan" <[email protected]>=0A> > > > > Cc: "=
[email protected]"=0A> > > > <[email protected]>=0A=
> > > > > Date: Thursday, 28 April, 2011, 12:38=0A> AM=0A> > > > > On Wed, =
Apr 27, 2011 at 1:12 AM,=0A> > > > > Mahmood Naderan <[email protected]>=
=0A> > > > > wrote:=0A> > > > > >>Change the order method. Have=0A> > hostb=
ased=0A> > > > before=0A> > > > > password=0A> > > > > >=0A> > > > > > Sorr=
y where should I do that?=0A> > > > > =0A> > > > > man ssh_config and look =
into=0A> > > PreferredAuthentications=0A> > > > > =0A> > > > > >=0A> > > > =
> > // Naderan *Mahmood;=0A> > > > > >=0A> > > > > > From: Asif Iqbal <vadu=
[email protected]>=0A> > > > > > To: Mahmood Naderan <[email protected]>=0A> =
> > > > > Cc: "[email protected]"=0A> > > > > <secureshell@secu=
rityfocus.com>=0A> > > > > > Sent: Wednesday, April 27, 2011=0A> 9:17=0A> >=
 AM=0A> > > > > > Subject: Re: problem with=0A> > > > HostbasedAuthenticati=
on=0A> > > > > >=0A> > > > > >=0A> > > > > > Change the order method. Have=
=0A> > hostbased=0A> > > before=0A> > > > > password=0A> > > > > > On Apr 2=
6, 2011 11:52 PM,=0A> "Mahmood=0A> > Naderan"=0A> > > > <[email protected]=
om>=0A> > > > > wrote:=0A> > > > > >>=0A> > > > > >>=0A> > > > > >> Hi,=0A>=
 > > > > >> I am trying to setup a=0A> hostbased=0A> > > passwrodless=0A> >=
 > > ssh=0A> > > > > from a client to a server using this=0A> guide=0A> > h=
ttp://www.ehow.com/how_7621307_set-up-hostbased-authentication.html.=0A> > =
> > > >>=0A> > > > > >> The client looks like:=0A> > > > > >>=0A> > > > > >=
> mahmood@client:~$ cat=0A> > > /etc/ssh/ssh_config=A0 |=0A> > > > grep=0A>=
 > > > > "HostbasedAuthentication"=0A> > > > > >> =A0=A0 HostbasedAuthentic=
ation=0A> yes=0A> > > > > >> mahmood@client:~$ cat=0A> > > /etc/ssh/ssh_con=
fig=A0 |=0A> > > > grep=0A> > > > > "EnableSSHKeysign"=0A> > > > > >> =A0=
=A0 EnableSSHKeysign yes=0A> > > > > >>=0A> > > > > >>=0A> > > > > >> and t=
he server looks like:=0A> > > > > >> mahmood@server:~$ cat=0A> > > /etc/ssh=
/sshd_config=A0=0A> > > > |=0A> > > > > grep "HostbasedAuthentication"=0A> =
> > > > >> HostbasedAuthentication yes=0A> > > > > >> mahmood@server:~$ cat=
=0A> > > /etc/ssh/sshd_config=A0=0A> > > > |=0A> > > > > grep "IgnoreRhosts=
"=0A> > > > > >> IgnoreRhosts no=0A> > > > > >>=0A> > > > > >> also the ser=
ver has the key=0A> for=0A> > client:=0A> > > > > >>=0A> > > > > >> mahmood=
@server:~$ cat=0A> > > > /etc/ssh/ssh_known_hosts=0A> > > > > >> client ssh=
-rsa AAAAB3Nz.....=0A> > > > > >>=0A> > > > > >> the ~/.shosts file on the=
=0A> server=0A> > > contains:=0A> > > > > >> mahmood@server:~$ cat .shosts=
=0A> > > > > >> client.domain mahmood=0A> > > > > >>=0A> > > > > >> Then on=
 both server and=0A> client, the=0A> > ssh=0A> > > > service is=0A> > > > >=
 restarted:=0A> > > > > >> mahmood@client:~$ sudo service=0A> ssh=0A> > > r=
estart=0A> > > > > >> ssh start/running, process=0A> 1355=0A> > > > > >> ma=
hmood@server:~$ sudo service=0A> ssh=0A> > > restart=0A> > > > > >> ssh sta=
rt/running, process=0A> 28982=0A> > > > > >>=0A> > > > > >> How, when I run=
 "ssh -vvv=0A> server"=0A> > from=0A> > > client=0A> > > > (to=0A> > > > > =
show the verbose messages), I still get=0A> the=0A> > > password=0A> > > > =
> prompt.=0A> > > > > >>=0A> > > > > >> mahmood@client:~$ ssh -vvv=0A> serv=
er=0A> > > > > >> OpenSSH_5.3p1=0A> Debian-3ubuntu6,=0A> > OpenSSL=0A> > > =
0.9.8k=0A> > > > 25=0A> > > > > Mar 2009=0A> > > > > >> debug1: Reading con=
figuration=0A> data=0A> > > > > /etc/ssh/ssh_config=0A> > > > > >> debug1: =
Applying options for=0A> *=0A> > > > > >> debug2: ssh_connect: needpriv=0A>=
 0=0A> > > > > >> debug1: Connecting to server=0A> > > [192.168.1.1]=0A> > =
> > port=0A> > > > > 22.=0A> > > > > >> debug1: Connection=0A> established.=
=0A> > > > > >> debug1: identity file=0A> > > > /home/mahmood/.ssh/identity=
=0A> > > > > type -1=0A> > > > > >> debug1: identity file=0A> > > > /home/m=
ahmood/.ssh/id_rsa=0A> > > > > type -1=0A> > > > > >> debug1: identity file=
=0A> > > > /home/mahmood/.ssh/id_dsa=0A> > > > > type -1=0A> > > > > >> deb=
ug1: Remote protocol=0A> version=0A> > 2.0,=0A> > > remote=0A> > > > > soft=
ware version OpenSSH_5.3p1=0A> > Debian-3ubuntu4=0A> > > > > >> debug1: mat=
ch: OpenSSH_5.3p1=0A> > > Debian-3ubuntu4=0A> > > > pat=0A> > > > > OpenSSH=
*=0A> > > > > >> debug1: Enabling compatibility=0A> mode=0A> > for=0A> > > =
> protocol=0A> > > > > 2.0=0A> > > > > >> debug1: Local version string=0A> =
> > > SSH-2.0-OpenSSH_5.3p1=0A> > > > > Debian-3ubuntu6=0A> > > > > >> debu=
g2: fd 3 setting=0A> O_NONBLOCK=0A> > > > > >> debug1: SSH2_MSG_KEXINIT sen=
t=0A> > > > > >> debug3: Wrote 792 bytes for a=0A> total=0A> > of=0A> > > 8=
31=0A> > > > > >> debug1: SSH2_MSG_KEXINIT=0A> received=0A> > > > > >> debu=
g2: kex_parse_kexinit:=0A> > > > >=0A> > > >=0A> > >=0A> >=0A> diffie-hellm=
an-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-=
group14-sha1,diffie-hellman-=0A> > > > > >> group1-sha1=0A> > > > > >> debu=
g2: kex_parse_kexinit:=0A> > > ssh-rsa,ssh-dss=0A> > > > > >> debug2: kex_p=
arse_kexinit:=0A> > > > >=0A> > > >=0A> > >=0A> >=0A> aes128-ctr,aes192-ctr=
,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-=
cbc,aes192-=0A> > > > > >> cbc,aes256-cbc,arcfour,[email protected].=
se=0A> > > > > >> debug2: kex_parse_kexinit:=0A> > > > >=0A> > > >=0A> > >=
=0A> >=0A> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cb=
c,3des-cbc,blowfish-cbc,cast128-cbc,aes192-=0A> > > > > >> cbc,aes256-cbc,a=
rcfour,[email protected]=0A> > > > > >> debug2: kex_parse_kexinit=
:=0A> > > > hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,hmac-ripe=
[email protected],hmac-sha1-96,hmac-=0A> > > > > >> md5-96=0A> > > > > >> d=
ebug2: kex_parse_kexinit:=0A> > > > hmac-md5,hmac-sha1,[email protected],=
hmac-ripemd160,[email protected],hmac-sha1-96,hmac-=0A> > > > > >>=
 md5-96=0A> > > > > >> debug2: kex_parse_kexinit:=0A> none,[email protected]=
,zlib=0A> > > > > >> debug2: kex_parse_kexinit:=0A> none,[email protected],z=
lib=0A> > > > > >> debug2: kex_parse_kexinit:=0A> > > > > >> debug2: kex_pa=
rse_kexinit:=0A> > > > > >> debug2: kex_parse_kexinit:=0A> > > first_kex_fo=
llows=0A> > > > 0=0A> > > > > >> debug2: kex_parse_kexinit:=0A> reserved=0A=
> > 0=0A> > > > > >> debug2: kex_parse_kexinit:=0A> > > > >=0A> > > >=0A> >=
 >=0A> >=0A> diffie-hellman-group-exchange-sha256,diffie-hellman-group-exch=
ange-sha1,diffie-hellman-group14-sha1,diffie-hellman-=0A> > > > > >> group1=
-sha1=0A> > > > > >> debug2: kex_parse_kexinit:=0A> > > ssh-rsa,ssh-dss=0A>=
 > > > > >> debug2: kex_parse_kexinit:=0A> > > > >=0A> > > >=0A> > >=0A> >=
=0A> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des=
-cbc,blowfish-cbc,cast128-cbc,aes192-=0A> > > > > >> cbc,aes256-cbc,arcfour=
,[email protected]=0A> > > > > >> debug2: kex_parse_kexinit:=0A> =
> > > >=0A> > > >=0A> > >=0A> >=0A> aes128-ctr,aes192-ctr,aes256-ctr,arcfou=
r256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-=0A> > =
> > > >> cbc,aes256-cbc,arcfour,[email protected]=0A> > > > > >> =
debug2: kex_parse_kexinit:=0A> > > > hmac-md5,hmac-sha1,[email protected]=
,hmac-ripemd160,[email protected],hmac-sha1-96,hmac-=0A> > > > > >=
> md5-96=0A> > > > > >> debug2: kex_parse_kexinit:=0A> > > > hmac-md5,hmac-=
sha1,[email protected],hmac-ripemd160,[email protected],hmac-sha=
1-96,hmac-=0A> > > > > >> md5-96=0A> > > > > >> debug2: kex_parse_kexinit:=
=0A> none,[email protected]=0A> > > > > >> debug2: kex_parse_kexinit:=0A> no=
ne,[email protected]=0A> > > > > >> debug2: kex_parse_kexinit:=0A> > > > > >=
> debug2: kex_parse_kexinit:=0A> > > > > >> debug2: kex_parse_kexinit:=0A> =
> > first_kex_follows=0A> > > > 0=0A> > > > > >> debug2: kex_parse_kexinit:=
=0A> reserved=0A> > 0=0A> > > > > >> debug2: mac_setup: found=0A> hmac-md5=
=0A> > > > > >> debug1: kex:=0A> server->client=0A> > > aes128-ctr=0A> > > =
> hmac-md5=0A> > > > > none=0A> > > > > >> debug2: mac_setup: found=0A> hma=
c-md5=0A> > > > > >> debug1: kex:=0A> client->server=0A> > > aes128-ctr=0A>=
 > > > hmac-md5=0A> > > > > none=0A> > > > > >> debug1:=0A> > > > >=0A> > >=
=0A> SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192)=0A> > > > sent=0A> > > > >=
 >> debug1: expecting=0A> > > SSH2_MSG_KEX_DH_GEX_GROUP=0A> > > > > >> debu=
g3: Wrote 24 bytes for a=0A> total=0A> > of=0A> > > 855=0A> > > > > >> debu=
g2: dh_gen_key: priv key=0A> bits=0A> > set:=0A> > > > 124/256=0A> > > > > =
>> debug2: bits set: 507/1024=0A> > > > > >> debug1:=0A> SSH2_MSG_KEX_DH_GE=
X_INIT=0A> > sent=0A> > > > > >> debug1: expecting=0A> > > SSH2_MSG_KEX_DH_=
GEX_REPLY=0A> > > > > >> debug3: Wrote 144 bytes for a=0A> total=0A> > of=
=0A> > > 999=0A> > > > > >> debug3:=0A> check_host_in_hostfile:=0A> > > fil=
ename=0A> > > > > /home/mahmood/.ssh/known_hosts=0A> > > > > >> debug3:=0A>=
 check_host_in_hostfile:=0A> > match=0A> > > line 1=0A> > > > > >> debug3:=
=0A> check_host_in_hostfile:=0A> > > filename=0A> > > > > /home/mahmood/.ss=
h/known_hosts=0A> > > > > >> debug3:=0A> check_host_in_hostfile:=0A> > matc=
h=0A> > > line 2=0A> > > > > >> debug1: Host 'server' is known=0A> and=0A> =
> > matches=0A> > > > the RSA=0A> > > > > host key.=0A> > > > > >> debug1: =
Found key in=0A> > > > > /home/mahmood/.ssh/known_hosts:1=0A> > > > > >> de=
bug2: bits set: 503/1024=0A> > > > > >> debug1: ssh_rsa_verify:=0A> signatu=
re=0A> > > correct=0A> > > > > >> debug2: kex_derive_keys=0A> > > > > >> de=
bug2: set_newkeys: mode 1=0A> > > > > >> debug1: SSH2_MSG_NEWKEYS sent=0A> =
> > > > >> debug1: expecting=0A> SSH2_MSG_NEWKEYS=0A> > > > > >> debug3: Wr=
ote 16 bytes for a=0A> total=0A> > of=0A> > > 1015=0A> > > > > >> debug2: s=
et_newkeys: mode 0=0A> > > > > >> debug1: SSH2_MSG_NEWKEYS=0A> received=0A>=
 > > > > >> debug1:=0A> SSH2_MSG_SERVICE_REQUEST=0A> > sent=0A> > > > > >> =
debug3: Wrote 48 bytes for a=0A> total=0A> > of=0A> > > 1063=0A> > > > > >>=
 debug2: service_accept:=0A> > ssh-userauth=0A> > > > > >> debug1:=0A> SSH2=
_MSG_SERVICE_ACCEPT=0A> > > received=0A> > > > > >> debug2: key:=0A> > > /h=
ome/mahmood/.ssh/identity=0A> > > > ((nil))=0A> > > > > >> debug2: key:=0A>=
 > /home/mahmood/.ssh/id_rsa=0A> > > > ((nil))=0A> > > > > >> debug2: key:=
=0A> > /home/mahmood/.ssh/id_dsa=0A> > > > ((nil))=0A> > > > > >> debug3: W=
rote 64 bytes for a=0A> total=0A> > of=0A> > > 1127=0A> > > > > >> debug1: =
Authentications that=0A> can=0A> > > continue:=0A> > > > > publickey,passwo=
rd,hostbased=0A> > > > > >> debug3: start over, passed a=0A> > different=0A=
> > > list=0A> > > > > publickey,password,hostbased=0A> > > > > >> debug3: =
preferred=0A> > > > >=0A> > > >=0A> > >=0A> >=0A> gssapi-keyex,gssapi-with-=
mic,gssapi,hostbased,publickey,keyboard-interactive,password=0A> > > > > >>=
 debug3: authmethod_lookup=0A> > hostbased=0A> > > > > >> debug3: remaining=
 preferred:=0A> > > > >=0A> publickey,keyboard-interactive,password=0A> > >=
 > > >> debug3: authmethod_is_enabled=0A> > hostbased=0A> > > > > >> debug1=
: Next authentication=0A> > method:=0A> > > > hostbased=0A> > > > > >> debu=
g2: userauth_hostbased:=0A> chost=0A> > > client.=0A> > > > > >> debug2: ss=
h_keysign called=0A> > > > > >> debug3: ssh_msg_send: type 2=0A> > > > > >>=
 debug3: ssh_msg_recv entering=0A> > > > > >> debug1:=0A> permanently_drop_=
suid:=0A> > 1000=0A> > > > > >> debug2: we sent a hostbased=0A> packet,=0A>=
 > wait=0A> > > for=0A> > > > > reply=0A> > > > > >> debug3: Wrote 608 byte=
s for a=0A> total=0A> > of=0A> > > 1735=0A> > > > > >> debug1: Authenticati=
ons that=0A> can=0A> > > continue:=0A> > > > > publickey,password,hostbased=
=0A> > > > > >> debug2: userauth_hostbased:=0A> chost=0A> > > client.=0A> >=
 > > > >> debug2: ssh_keysign called=0A> > > > > >> debug3: ssh_msg_send: t=
ype 2=0A> > > > > >> debug3: ssh_msg_recv entering=0A> > > > > >> debug1:=
=0A> permanently_drop_suid:=0A> > 1000=0A> > > > > >> debug2: we sent a hos=
tbased=0A> packet,=0A> > wait=0A> > > for=0A> > > > > reply=0A> > > > > >> =
debug3: Wrote 672 bytes for a=0A> total=0A> > of=0A> > > 2407=0A> > > > > >=
> debug1: Authentications that=0A> can=0A> > > continue:=0A> > > > > public=
key,password,hostbased=0A> > > > > >> debug1: No more client=0A> hostkeys=
=0A> > for=0A> > > > hostbased=0A> > > > > authentication.=0A> > > > > >> d=
ebug2: we did not send a=0A> packet,=0A> > > disable=0A> > > > method=0A> >=
 > > > >> debug3: authmethod_lookup=0A> > publickey=0A> > > > > >> debug3: =
remaining preferred:=0A> > > > > keyboard-interactive,password=0A> > > > > =
>> debug3: authmethod_is_enabled=0A> > publickey=0A> > > > > >> debug1: Nex=
t authentication=0A> > method:=0A> > > > publickey=0A> > > > > >> debug1: T=
rying private key:=0A> > > > > /home/mahmood/.ssh/identity=0A> > > > > >> d=
ebug3: no such identity:=0A> > > > > /home/mahmood/.ssh/identity=0A> > > > =
> >> debug1: Trying private key:=0A> > > > > /home/mahmood/.ssh/id_rsa=0A> =
> > > > >> debug3: no such identity:=0A> > > > > /home/mahmood/.ssh/id_rsa=
=0A> > > > > >> debug1: Trying private key:=0A> > > > > /home/mahmood/.ssh/=
id_dsa=0A> > > > > >> debug3: no such identity:=0A> > > > > /home/mahmood/.=
ssh/id_dsa=0A> > > > > >> debug2: we did not send a=0A> packet,=0A> > > dis=
able=0A> > > > method=0A> > > > > >> debug3: authmethod_lookup=0A> password=
=0A> > > > > >> debug3: remaining preferred:=0A> > ,password=0A> > > > > >>=
 debug3: authmethod_is_enabled=0A> > password=0A> > > > > >> debug1: Next a=
uthentication=0A> > method:=0A> > > password=0A> > > > > >> mahmood@server'=
s password:=0A> > > > > >>=0A> > > > > >>=0A> > > > > >> Any idea about tha=
t?=0A> > > > > >>=0A> > > > > >> // Naderan *Mahmood;=0A> > > > > >>=0A> > =
> > > >=0A> > > > > =0A> > > > > =0A> > > > > =0A> > > > > -- =0A> > > > > =
Asif Iqbal=0A> > > > > PGP Key: 0xE62693C5 KeyServer:=0A> pgp.mit.edu=0A> >=
 > > > A: Because it messes up the order in=0A> which=0A> > > people=0A> > =
> > normally=0A> > > > > read text.=0A> > > > > Q: Why is top-posting such =
a bad=0A> thing?=0A> > > > >=0A> > > >=0A> > > =0A> > >=0A> > =0A> >=0A> =
=0A>